Denial of Service Vulnerability in Intel Gaudi Software Hardware Plugin
CVE-2026-27765

6.8MEDIUM

What is CVE-2026-27765?

The vLLM Hardware Plugin designed for Intel Gaudi Software prior to version 0.16.0 has a vulnerability due to improper input validation. An authorized user with minimal expertise could exploit this flaw to induce a denial of service condition. The attack may be executed locally, requiring no specific internal knowledge or user interaction. This vulnerability highlights potential risks regarding the availability of the affected system, leading to significant disruptions in service functions without compromising confidentiality or integrity.

Affected Version(s)

vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.